NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #997 by repository stars
Last release 7 days ago
10 Sep 2026
Ships fairly regularly
a new release about every 1 weeks
Most releases are documented
notes for 53 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 months old
139 releases · first in 2025
One column per month.
Nothing published for this version
ADDED: Mass delete sets — you can now select multiple sets at once and delete them all together. Click the "Select" button in the toolbar, check the s
.dat files directly from your computer using the "Upload" button in Settings > Geo Databases.80,5222,8000-9000) in the TCP settings tab, just like UDP. Port 443 is always included. Firewall rules, packet processing, and the monitor all update automatically — no restart needed. Useful for services like Telegram (port 5222), WhatsApp (5222-5223), Signal (4433), XMPP, and others that use non-443 TCP ports.Settings > Core > Queue Settings instead of being tied to a specific set.b4_version tag is included so you can tell which B4 version a shared set was made with.veth interfaces (used by MikroTik containers) were incorrectly hidden. They now show up properly in the interface list.Nothing published for this version
ADDED: MSS Clamping — forces smaller packet sizes at the firewall level so that blocked content (like YouTube on smart TVs) can load correctly. Two op
Settings > Network > Global MSS Clamping, or set a per-device size in the Settings > Device Filtering table (MSS column). Changes apply instantly without restarting.NAT Masquerade in Settings > Feature Flags > Firewall Features and optionally pick an output interface. Works with both iptables and nftables. Rules are monitored and auto-restored if they disappear. Also available via CLI: --masquerade and --masquerade-interface.Capture feature) would lose the payload reference after being added, causing the bypass to fail. The payload type also didn't show correctly in the set editor until manually reselected. Both are now fixed.Discovery finds the optimal Fake TTL for Combo configurations automatically by scanning through preset TTL values, and tests all faking strategies (including timestamp) to pick the most reliable one.--config flag is no longer required. When omitted, B4 automatically looks for a config file in /etc/b4/ and /opt/etc/b4/. If no config exists yet, B4 picks the best default location and creates one on first run.CHANGED: Vendor Lookup is now optional — the ~6MB device manufacturer database is no longer downloaded at startup. Enable it in Settings > Device Filt
Settings > Device Filtering > Vendor Lookup if you want to see device brand names.Auto / TLS 1.2 / TLS 1.3) to use when probing.Settings > Network Configuration > SOCKS5 Server. Supports optional username/password authentication. (#48, thanks @remmody)docker pull instructions instead of the update button.veth and other container interfaces when running inside Docker/MikroTik. (#44, thanks @kakosmakos)ADDED: HTTPS/TLS support for the web interface (#40, thanks @Shiperoid). Configure in Web UI (Settings > Network > Web Server) or in the config JSON.
Settings > Network > Web Server) or in the config JSON. The installer auto-detects router certificates on OpenWrt and Asus Merlin and offers to enable HTTPS during installation.Settings > Core Controls).IMPROVED: Connections Table — moved the streaming/paused control from the top control bar to a floating play/stop button in the bottom-right corner of
Fragmentation and Faking tabs are now part of the TCP section where they belong, since both techniques operate on TCP traffic.
General (connection limits, timing, duplication), Splitting (all packet splitting strategies), and Faking (all evasion techniques in one place).Faking groups related settings into collapsible sections (Fake SNI, SYN Fake, Desync, Window Manipulation, Incoming Response Bypass, ClientHello Mutation) — each section shows its current status at a glance so you can see what's active without opening it.UDP, DNS, Targets, and Import/Export tabs remain unchanged.FIXED: All changes being lost and tabs resetting when creating a new set. Any edit (switching tabs, adding categories, changing settings) could be ran
set. Any edit (switching tabs, adding categories, changing settings) could be randomly undone.Oscillate or Random window modes.Packet Duplication connections showing incorrect data in the connections table.IMPROVED: Geo Settings - GeoSite and GeoIP databases can now be downloaded independently from different sources. You no longer need both files — pick
GeoSite and GeoIP databases can now be downloaded independently from different sources. You no longer need both files — pick only what you need. Added b4geoip as a built-in source option.ADDED: Randomized Segment 2 Delay - instead of a fixed delay between TCP/UDP segments, you can now set a min–max range. Each packet picks a random del
Dashboard - the dashboard now shows what actually matters:
Set editor now opens as a full page instead of a popup window, giving you much more space to work with when configuring your bypass sets.TCP Timestamp faking strategy - a new way to make fake packets look wrong to the real server (so it ignores them) while still fooling DPI. Instead of using a low TTL or wrong sequence number, B4 sends fake packets with an outdated timestamp. Inspired by the youtubeUnblock project. Select TCP Timestamp in the Faking strategy dropdown to use it.ClientHello payload generation.Nothing published for this version
Nothing published for this version
ADDED: Validation tries setting in Discovery - require multiple successful connections before accepting a configuration as reliable (default: 1, confi
Discovery - require multiple successful connections before accepting a configuration as reliable (default: 1, configurable 1-5). Helps filter out unstable bypass methods.youtube.com, B4 now tracks which IP addresses belong to that domain and properly handles all UDP traffic to those IPs, not just the initial connection.QUIC traffic even when not actively filtering those connections.FIXED: Custom payload files not working in Discovery feature - old configurations with relative paths like captures/payload.bin now work correctly.
Discovery feature - old configurations with relative paths like captures/payload.bin now work correctly.Nothing published for this version
ADDED: TCP MD5 preset in Discovery - automatically tests TCP MD5 bypass strategy during configuration discovery.
TCP MD5 bypass strategy during configuration discovery.iptables multiport module support - improves firewall rule efficiency when filtering multiple ports. The installer now detects and uses the multiport extension when available.FIXED: White screen when importing old set configurations (sets saved before v1.29 now automatically convert to current format).
ADDED: Custom payload support in Discovery - test bypass strategies using your own captured TLS payloads instead of built-in defaults.
Discovery - test bypass strategies using your own captured TLS payloads instead of built-in defaults.Discovery when checking status (e.g. clicking "Create Set" or refreshing page while discovery is running. Reported by Andrew B.).ADDED: Incoming response bypass - defeats TSPU throttling that blocks downloads after ~15KB. I nmost cases - select TCP incoming fake for all strategi
fake for all strategies.Nothing published for this version
ADDED: Web server bind address setting - control which network interface the web UI listens on (e.g., 127.0.0.1 for localhost-only access, 0.0.0.0 for
127.0.0.1 for localhost-only access, 0.0.0.0 for all interfaces). Supports IPv6.Skip DNS toggle in Discovery - useful when you know DNS isn't blocked and want faster results.MIPS devices with soft float.Post-ClientHello RST toggle in TCP Desync Set settings.Discovery now finds the optimal TTL for a specific network, instead of using a fixed value.nftables (e.g., OpenWrt with fw4 firewall).desync bypass methods (rst, fin, ack, combo, full modes) were sending malformed packets, causing them to fail or be ignored. Affects both IPv4 and IPv6.Packet Mark setting in Network Configuration - allows customizing the firewall mark used for traffic routing.overlap — functionality merged into combo.combo now supports decoy packets. When enabled, B4 sends a fake ClientHello with a whitelisted domain (e.g., ya.ru, vk.com) before sending the real fragmented request. Can be found in Fragmentaiton Tab set settings.FIXED: Adding multiple services with many UDP ports (Discord, WhatsApp, etc.) could cause iptables firewall rules to fail, preventing B4 from starting
iptables firewall rules to fail, preventing B4 from starting or restarting properly.FIXED: DNS poisoning detection should correctly compare IP lists from system resolver vs encrypted DNS, even when IPs are returned in different order.
ADDED: Discovery Logs panel shows real-time progress during configuration discovery.
Discovery Logs panel shows real-time progress during configuration discovery.Instagram, Facebook, YouTube, Twitter/X, Telegram, Discord, TikTok, Netflix, Spotify, etc). Discovery now uses full IP ranges instead of single DNS results. View supported servicesDiscovery Logs panel now shows more detailed real-time progress during DPI fingerprinting, DNS checks, and strategy testing.Discovery now uses DNS-over-HTTPS (encrypted DNS via Google/Quad9/Cloudflare) to detect when your ISP returns fake IP addresses for blocked sites. When DNS poisoning is detected, B4 connects directly to the real server to continue testing bypass strategies.QUIC traffic (used by YouTube, Google, and many modern sites) was ignored when custom UDP ports were configured for any target set. Now UDP port 443 is always monitored regardless of other port settings.FIXED: UDP port ranges (e.g., 50000-50032) now work correctly on both iptables and nftables systems. Previously, port ranges could cause startup failu
50000-50032) now work correctly on both iptables and nftables systems. Previously, port ranges could cause startup failures on older devices.Targets (separated by spaces, commas, or pipes).FIXED: Normalize UDP port filter format by replacing dashes with colons before creating UDP rules in the iptables.
iptables.Discovery now detects when DPI blocks downloads mid-transfer (e.g., cuts connection after 16KB), potentially preventing false "success" reports.Payload capture always showing "timeout" even when visiting the target site correctly.ADDED: Upload Custom Payloads - upload your own binary payload files instead of capturing from live traffic (avilable in the Settings -> Capture tab).
Settings -> Capture tab).My own Payload file option in Faking settings lets you use previously captured or uploaded payload binaries.Discovery, B4 automatically finds and includes matching geosite categories (e.g., discovering youtube.com will also add the youtube category with related domains from it).https://youtube.com/watch?v=xyz or https://cdn.example.com/large-file.js instead of just a domain name.seqovl. Configure a custom byte pattern in Fragmentation settings that gets mixed into TCP segments to confuse deep packet inspection systems while your real data reaches the server intact. Works with disorder and combo strategies.443 (QUIC) by default instead of all UDP ports, reducing unnecessary packet processing.Device Filtering is enabled in Settings.geosite.dat/geoip.dat) were manually deleted.IPv6 bypass settings now work correctly - disabling IPv6 in config actually disables IPv6 packet processing.Nothing published for this version
FIXED: installer failing to download on OpenWRT devices - improved compatibility with minimal BusyBox environments.
OpenWRT devices - improved compatibility with minimal BusyBox environments.OpenWRT routers.FIXED: nftables forwarded traffic not working on OpenWRT - changed hook from POSTROUTING to FORWARD to capture packets before NAT.
nftables forwarded traffic not working on OpenWRT - changed hook from POSTROUTING to FORWARD to capture packets before NAT.FIXED: add validation for fake SNI bounds and fallback to TCP fragments in overlap handling.
overlap handling.overlap fragment handling.Nothing published for this version
REMOVED: --skip-local-traffic as it did actually nothing causing connection issues and solving real problem.
--skip-local-traffic as it did actually nothing causing connection issues and solving real problem.Connections - identify which device (phone, laptop, etc.) is making each connection, with optional per-device filtering (whitelist/blacklist) in Settings.Settings → DevicesConnections table filtering:
+ (e.g., tcp+youtube)! prefix (e.g., !google or tcp+!udp)domain:, asn:, device: (e.g., domain:youtube+!asn:cloudflare)ADDED: --skip-local-traffic option to exclude router-originated traffic from processing, enabling compatibility with transparent proxies (Xray, Clash,
--skip-local-traffic option to exclude router-originated traffic from processing, enabling compatibility with transparent proxies (Xray, Clash, Sing-Box etc.) running on the same device. By default is on. Can be found in Core settings. Requires service restart when changing.eth0, tun0). Empty selection = all interfaces. Configurable via UI without service restart (can be found in Core settings).Panic errors are logged into errors.log.FIXED: crash in overlap fragmentation strategy when SNI extends beyond payload bounds (index out of range panic).
overlap fragmentation strategy when SNI extends beyond payload bounds (index out of range panic).panic errors not being captured to errors.log file.ADDED: dd error logging functionality with configurable error log file (default is /var/log/b4/errors.log) for crash diagnostics.
/var/log/b4/errors.log) for crash diagnostics.ASN filtering in Connections table - filter by ASN name globally or with asn: field filter.connection byte limits both iun UI and backend.FIXED: Discovery UI showing "0 of 0 checks" and "NaN%" during DNS detection phase.
Discovery UI showing "0 of 0 checks" and "NaN%" during DNS detection phase.Discovery completing too fast causing "Failed to fetch discovery status" error.ADDED: DNS Redirect - bypass ISP DNS poisoning by transparently rewriting queries to clean resolvers. Available at set level, allowing per-domain DNS
DNS Redirect - bypass ISP DNS poisoning by transparently rewriting queries to clean resolvers. Available at set level, allowing per-domain DNS redirect control.Enter hotkey to start discovery. (#5).Discovery fragmentation configurations and add new presets for combo and disorder strategies.installer.sh).ADDED: TCP SYN Fake TTL slider option.
SYN Fake TTL slider option.Overlap fragmentation option.FIXED: Slow set save operations - improve performance.
FIXED: Slow set save operations - improve performance.
ADDED: New FRAG strategies designed for modern DPI (TSPU):
Combo (recommended) - multi-technique: first-byte delay + extension split + SNI split + disorderDisorder - sends real segments out-of-order with timing jitter, no fake packetsOverlap - overlapping TCP segments where second overwrites first (RFC 793 behavior)Extension Split - splits TLS ClientHello within extensions array before SNIFirst-Byte Desync - sends 1 byte, delays, sends rest (exploits DPI timeouts)Hybrid - evasion strategy combining desync, fake SNI, and disorder techniquesIMPROVED: Skip private destination IP packets processing.
FIXED: Discovery false positives - now detects mid-transfer DPI blocking (throttling, stalls, resource blocking) instead of trusting initial HTTP 200.
Discovery false positives - now detects mid-transfer DPI blocking (throttling, stalls, resource blocking) instead of trusting initial HTTP 200.Discovery network baseline - measures reference domain speed first, requires target to achieve 4KB+ downloaded at 30%+ of baseline speed. Configurable reference domain in Settings → Discovery (default: yandex.ru).Discovery binary search optimization for TTL and fragmentation position parameters - reduces Phase 2 tests from ~50 to ~15 while finding optimal values. Uses fingerprint hints when available.Sets editor save button now shows immediate loading feedback with spinner and disabled state to prevent double-submit during slow saves.Sets manager now supports drag-and-drop reordering instead of up/down arrows.FIXED: IPv4 UDP fragmentation using incorrect fragment offset encoding (wrong bit shifts corrupted offset field).
Discovery service testing all presets with single hardcoded fake SNI payload - if user's DPI only responds to alternate payload, most strategies would incorrectly fail.tcp_check and md5sum faking strategies for checksum corruption fallback when TTL-based faking is unreliable.DPI Fingerprinting in Discovery - attempts to identify DPI type and blocking method before testing, prioritizing likely-effective strategies based on failure mode analysis. May produce inaccurate results; falls back automatically to full preset scan when fingerprint is inconclusive.FakeSNI1: google (default, AKA classic), FakeSNI2: duckduckgo) - different DPI systems respond to different payloads.Fragmentation UI - renamed "Middle SNI" to "Smart SNI Split", added visual packet diagram, moved manual position to collapsible advanced section.FIXED: IPv4 UDP fragmentation using incorrect fragment offset encoding (wrong bit shifts corrupted offset field).
tcp_check and md5sum faking strategies for checksum corruption fallback when TTL-based faking is unreliable.Fragmentation UI - renamed "Middle SNI" to "Smart SNI Split", added visual packet diagram, moved manual position to collapsible advanced section.FIXED: New sets with geosite/geoip categories not matching traffic until service restart.
ADDED: Filter for configuration sets - search by name, SNI domains, geosite categories, or geoip categories.
name, SNI domains, geosite categories, or geoip categories.Discovery now names new sets after the preset configuration (e.g., tcp-frag-rev-fake) instead of the domain.Discovery detects similar existing sets and offers to add the domain to an existing set instead of creating a new one.Discovery short-circuits when baseline succeeds - skips optimization phases if no DPI is detected.Discovery shows results progressively as tests complete - users can see working configurations and apply them without waiting for the full scan to finish./api/sets) for CRUD operations - create, update, delete, and reorder sets independently.Discovery configuration refactoring component.FIXED: revert back the Fake SNI payload for improved compatibility.
CHANGED: update set default desync mode to 'off'.
desync mode to 'off'.FIXED: Domains table not updating with new packets due to React state reference issue.
Domains table not updating with new packets due to React state reference issue.Domains table columns layout being cramped with fixed widths.ADDED: ClientHello Mutation support for IPv6.
ClientHello Mutation support for IPv6.SNI Mutation, TCP Window, and Desync settings.FIXED: Unable to change ClientHello Mutation mode in the Faking settings.
ClientHello Mutation mode in the Faking settings.IMPROVED: Overall performance (frontend and backend).
TCP Window Manipulation (--tcp-win-mode) - sends fake packets with manipulated TCP window sizes to confuse stateful DPI. Modes: oscillate (cycling window values), zero (zero-window probe attack), random (randomized windows), escalate (gradually increasing windows).TCP Desync Attack (--tcp-desync-mode) - injects fake TCP control packets (RST/FIN/ACK) with low TTL and corrupted checksums to desynchronize DPI connection tracking. Modes: rst, fin, ack, combo, full.SNI Mutation for ClientHello fingerprint evasion - modifies TLS handshake structure to bypass DPI fingerprinting. Modes: duplicate (inject fake SNIs), grease (add GREASE extensions), padding (add padding extension), reorder (shuffle extensions), full (all mutations combined), advanced (TLS 1.3 features like PSK/key_share).ADDED: Out-of-Band (OOB) data handling with configurable position, reverse order, and character (--frag=oob).
Out-of-Band (OOB) data handling with configurable position, reverse order, and character (--frag=oob).Out-of-Band (OOB) strategies to B4Discovery.TLS Record Splitting fragmentation strategy (--frag=tls) - splits ClientHello into multiple TLS records to bypass DPI expecting single-record handshakes.SACK dropping (--tcp-drop-sack) - strips Selective Acknowledgment options from TCP headers to force full retransmissions and confuse stateful DPI tracking.SNI payload now uses TLS 1.3 ClientHello structure with staticcdn.duckduckgo.com.SNI fragmentation for long domains (>30 bytes). Now splits 12 bytes before SNI end instead of middle, ensuring domain suffixes like googlevideo.com are properly fragmented across packets.Matcher performance with LRU caching for large geosite/geoip categories (70-90% CPU reduction for sets with big data inside).Geodat download workflow - files now immediately available in sets manager without restart, config auto-reloads after download.Fragmentation tab refactored.TCP ConnBytesLimit greater than main set error.--frag-sni-reverse to --frag-reverse and update related configurations.Nothing published for this version
ADDED: Asynchronous packet injection for TCP and UDP traffic. Verdict is now sent to kernel immediately, with packet manipulation performed in paralle
1ms sleep delays when Seg2Delay is set to 0, reducing packet processing latency by up to 6ms per QUIC packet.ADDED: Configuration sets can now be enabled/disabled without deletion.
GeoSite/GeoIP database files directly from Settings UI with preset sources./test page UX - domains are now managed directly on the test page.Discovery presets generation logic and add new test strategies./domains page when adding ASN filters (caused by expensive ASN lookup operations executing on every render).Settings - domains are now managed exclusively on the Test page.ADDED: SYN fake packet functionality for advanced DPI bypass. Sends fake SYN packets with configurable payload length to confuse DPI systems before th
--tcp-syn-fake and --tcp-syn-fake-len flags, or through the TCP settings in Web UI.IPInfo API integration. When IPInfo token is configured in Settings → API, click on any destination IP in /domains monitoring page to view detailed geolocation, ASN, organization, and network information.RIPE Stat integration for network intelligence. View ASN prefix announcements and detailed network information directly from the Web UI. Helps identify IP ranges for precise targeting.ADDED: Select target configuration set when adding domains or IP/CIDR addresses from /domains monitoring page. Allows precise control over which confi
/domains monitoring page. Allows precise control over which configuration set receives the new entry.Discovery test results. Apply the best-performing configuration directly to your configuration list without manual copying.Discovery testing service with improved reliability and performance. Now they should work as expected.ADDED: Click on destination IP addresses in /domains monitoring page to add them to configuration. Modal allows adding either exact IP or CIDR notatio
/domains monitoring page to add them to configuration. Modal allows adding either exact IP or CIDR notation for broader site coverage. This does not require to reload or restart B4, works on the fly./domains monitoring page to view all packets or only those with identified SNI/domain. Useful for monitoring and debugging UDP traffic./test menu. Discovery test results now show individual configuration cards per domain instead of a single recommended configuration, making it easier to see what works best for each specific domain.UDP port filtering now uses a single flexible field instead of separate "from" and "to" fields. Supports comma-separated ports and ranges (e.g., 80,443,2000-3000)./domains menu now only counts packets processed by B4 targets.--udp-dport-min and --udp-dport-max flags with single --udp-dport-filter flag for flexible port filtering.UDP entries are now logged even when UDP packets are configured to be ignored in the configurationUI crash when using filter in /domains monitoring page.HTTP status code. Any HTTP response (including non-200 codes) indicates successful DPI circumvention.ADDED: Configuration Sets - fine-grained bypass control for different targets
geoip.dat support.ADDED: DPI Bypass Test feature to verify that circumvention is working. The feature tests configured domains and measures download speeds to ensure B4
/test page to run tests and /settings/checker to configure test settings (define which domains to test, etc.).Core tab on the Settings page.RESTART B4 BUTTON to the Core tab on the Settings page (under the Core Controls section).flowState struct to track SNI detection and processing status.Entware/OpenWRT/systemctl).P key on the domains and logs pages) interfering with search input.Your coding agent can read these notes before it upgrades. Set up the MCP server →